Management of Information Security, Fourth Edition 8-1
Chapter 8
Risk Management: Identifying and Assessing Risk
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Management of Information Security, Fourth Edition 8-2
Lecture Notes
Overview
Chapter 8 introduces students to the topic of risk management, and the use of different risk
management techniques. Students will learn about risk identification using different
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Define risk management and its role in the organization
Teaching Tips
Introduction
1. Educate students on the use of information security in organizations to manage risk,
and note that risk management is a key responsibility of managers.
Risk Management
1. Provide students with General Sun Tzu’s observation, and explain how it relates to
information security.
Knowing Yourself
1. Point out that risk is always involved when operating any kind of organization, and
provide some examples of potential risks than an organization may face.
Management of Information Security, Fourth Edition 8-3
Knowing the Enemy
1. Define risk management as the process of discovering and assessing the risks to an
Accountability for Risk Management
1. Discuss the strategic roles that each of the three communities must fulfill in order to
manage risks.
Risk Identification
1. Explain how managers identify assets, classify and categorize assets into groups, and
Creating an Inventory of Information Assets
1. Educate students on the risk identification process, and note the different types of
information assets that this can include.
2. Provide students with an example of assets that might be included in risk identification,
4. Explain how some organizations make use of an inventory management database
system to track assets.
5. List some of the potential attributes that could be used within an automatic or manual
inventory tracking system:
a. Name
Management of Information Security, Fourth Edition 8-4
i. Software version, update revision, or FCO number
6. Define a field change order (FCO) as occurring when a manufacturer upgrades a piece
of hardware at a customer’s premises.
7. Discuss the difficulty of identifying and documenting human resources, documentation,
Classifying and Categorizing Assets
1. Educate students on how to determine whether asset categories are meaningful to an
organization’s risk management program, and note that they may require further sub
categorization.
Assessing Values for Information Assets
1. Describe how relative values should be assigned to individual assets, and explain
relative values as comparative judgments in order to aid in prioritization when
performing risk management.
Teaching
Tip
A good example of a software inventory management program is OCS Inventory
NG:
Teaching
Tip
Asset tags are commonly used with servers and workstations within
organizations. In fact, companies such as Dell and HP often tag their equipment
Teaching
Categorization of assets can be difficult, especially in the case of servers that
Management of Information Security, Fourth Edition 8-5
Listing Assets in Order of Importance
1. Explain that the listing of assets in order of importance is the final step in risk
identification, and demonstrate how to do this.
Threat Identification
1. Reiterate that the ultimate goal of risk identification is to assess the circumstances and
setting of each information asset to reveal vulnerabilities.
2. Explain threat identification as involving the assessment of potential weaknesses in an
information asset.
3. Make students aware of the futility of focusing on every possible threat an information
asset may face.
Quick Quiz 1
1. The assessment of potential weaknesses or vulnerabilities of a specific information
asset is known as ____________________.
2. True or False: Only the InfoSec and IT communities have a role to play in the
management of risks to information assets.
Teaching
Tip
TechNet article on security planning for a web site, including threat
identification:
Management of Information Security, Fourth Edition 8-6
3. Which of the following occurs when a manufacturer performs an upgrade to a hardware
component at a customer’s premises?
A. Asset type
B. Field change order
C. Controlling entity
D. Manufacturer’s model or part number
4. The simplified risk management components, often referred to as PPT, consist of which
of the following?
A. People, planning, technology
B. Planning, performing, tasking
C. Preparedness, planning, and technology
D. People, process, and technology
5. Which term below defines the identification and assessment of levels of risk within an
organization?
A. Risk assessment
B. Risk analysis
C. Risk identification
D. Risk management
Methods of Assessing Threats
1. Talk to students about the 2012 survey asking executives about the basis used for
The TVA Worksheet
1. Note that an organization should have a prioritized list of assets and their vulnerabilities
by the end of the risk identification process, as well as a list that prioritizes threats faced
Risk Assessment
1. Explain to students that the assessment of relative risk for vulnerabilities is called risk
assessment, and note that this is accomplished by using a risk rating or score for
specific vulnerabilities.
Management of Information Security, Fourth Edition 8-7
Introduction to Risk Assessment
1. Discuss some of the different factors that are involved in the creation of a risk-rating
Likelihood
1. The likelihood of a risk should be explained as the possibility or probability that a
specific vulnerability will be exploited.
Assessing Potential Loss
1. Describe to students how to use weighted scores based on the value of an information
Percentage of Risk Mitigated by Current Controls
1. Explain that if a vulnerability is fully managed by an existing control, it may be set
Uncertainty
1. Emphasize that there is always an amount of uncertainty in making these assessments,
Risk Determination
1. Teach students that risk equals likelihood of vulnerability occurrence times value (or
Likelihood and Consequences
Management of Information Security, Fourth Edition 8-8
1. Discuss the likelihood and consequences rating created by the Australian and New
3. Educate students about the five levels used to rate the potential impact of a specific
threat occurring:
a. Level 1: Insignificant
4. Explain the five different qualitative likelihood assessment levels, ranging from A to E:
a. A: Almost certain
5. Describe to students how these two different tables can be combined in order to assess
Identify Possible Controls
1. Explain to students the importance of creating a preliminary list of control ideas for
each threat and its associated vulnerabilities that have residual risk.
2. Define residual risks as risks that remain even after existing controls, safeguards, or
countermeasures have been applied.
Access Controls
1. Explain how access controls are used to allow or deny users into trusted areas of an
organization, such as information systems, or physically restricted areas.
Management of Information Security, Fourth Edition 8-9
Documenting the Results of Risk Assessment
1. Explain the ranked vulnerability risk worksheet as the final summarized document
2. Demonstrate how to use a weighted spreadsheet to calculate risk vulnerability for
multiple information assets, and list some of the table columns such a document might
3. Students should understand that the risk identification process should designate what
function reports serve, who is responsible for preparing them, and who reviews them.
4. Educate students on some of the deliverables that should be completed by an
information asset risk management team:
5. Explain to students that the last stage of risk analysis involves the use of a TVA
worksheet, in combination with other worksheets, to develop a prioritized list of tasks.
Quick Quiz 2
1. The ____________________ of a threat is the overall rating, or numerical value, of the
probability that a specific vulnerability will be exploited.
2. True or False: The TVA worksheet is a combination of a prioritized list of assets and
their vulnerabilities, and a list of prioritized threats facing the organization based on a
weighted table.
3. The __________ uses categories instead of specific values to determine risk.
4. In the likelihood and consequences rating from the Australian and New Zealand Risk
Management Standard 4360, a risk level of 5 indicates what level of consequences?
A. Insignificant
B. Moderate
C. Major
D. Catastrophic
Management of Information Security, Fourth Edition 810
5. What is the formula for calculating risk?
A. (value * likelihood) risk mitigated + uncertainty = risk
B. (value * risk mitigated) + likelihood uncertainty = risk
C. (value * uncertainty) + likelihood risk mitigated = risk
D. (likelihood * uncertainty) + risk mitigated value = risk
Class Discussion Topics
1. Have students discuss how to calculate uncertainty when performing risk assessment.
How is uncertainty calculated and factored into an overall risk assessment?
Additional Projects
1. Provide groups of students with a scenario based on an imaginary organization, and
2. Get students to research different types of inventory management software that could
Additional Resources
1. FEMA document on Risk Assessment / Risk Management: